I´m trying to integrate MISP using the documentation using filebeat but no go. I´ve tried both (Misp module and Threatintel module) and none of them gets into ELK Stack.
Follow the errors from filebeat journalctl:
{"log.level":"error","@timestamp":"2022-05-19T16:37:42.021-0300","log.logger":"input.httpjson-cursor","log.origin":{"file.name":"httpjson/request.go","file.line":353},"message":"error processing response: expected map but type is []interface {}","service.name":"filebeat","id":"CAF1EDC614DA8C15","input_source":"https://10.130.0.240/events/restSearch","input_url":"https://XX.XX.XX.XX/events/restSearch","ecs.version":"1.6.0"}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.